agent 経由のアップデート
agent は万能インストーラーです。対象ホストで動き出してしまえば、他のどのコンポーネントをアップデートするときも operator がホストに直接触る必要はありません — agent が話している backend も、メッセージを運ぶブローカーも、agent 自身も対象です。
この章はコンポーネントごとに 1 ページずつあります:
全コンポーネントで共通の仕組み:
| バケット / ストリーム | 用途 |
|---|---|
OBJECT_APP_PACKAGES | 汎用バイナリストレージ (backend、client、NATS サーバーなど)。キーは <name>/<version>。 |
OBJECT_SCRIPTS | マニフェストが script_object で参照する PowerShell スクリプト本体。キーは <name>/<version>。 |
OBJECT_AGENT_RELEASES | agent バイナリ専用。agent の rollout 専用の watcher / target_version フローを持つので APP_PACKAGES とは別バケットになっています。 |
agent_config (KV) | レイヤード config — global / グループ別 / PC 別。target_version はここに置かれます。 |
jobs (KV) | ジョブカタログ。各エントリは operator が exec できるマニフェストです。 |
CLI コマンド一覧:
kanade app, kanade script and kanade agent (publish / rollout / current / logs) talk to the backend HTTP API, not to NATS: they need KANADE_AUTH_TOKEN (see kanade login) for an account with the operator role, and no broker token. Publishes and deletes are audited against that account by the backend. Operators who previously relied on the NATS token alone must now export KANADE_AUTH_TOKEN; without it the backend answers 401 / 403. kanade agent publish is capped by the backend at 64 MB for the whole upload (a normal agent binary is well under that). app publish additionally downloads the package back from the backend and checks its digest before reporting success.
| コマンド | 動作 |
|---|---|
kanade app publish <name> <file> [--version <version>] | Upload to OBJECT_APP_PACKAGES through the backend API. |
kanade script publish <name> <version> <file> | Upload to OBJECT_SCRIPTS through the backend API. |
kanade job create <yaml> | jobs KV にジョブマニフェストを upsert。 |
kanade exec <job-id> --pcs <pc> [--pcs <pc> …] | 登録済みジョブを PC 群に対して起動。 |
kanade agent publish <file> [--version <version>] | Upload an agent binary through the backend API (version extracted from PE VERSIONINFO; --version for a Linux / macOS binary). |
kanade agent rollout <version> --pc \| --group \| --global | Flip target_version on the chosen scope; agents pick it up via their self-update watcher. Goes through the backend API. |
kanade agent current | Print the global target_version (group / pc overlays are not shown; use kanade config get --group/--pc). |
kanade agent logs <pc_id> [--tail <n>] | Tail an online agent's log via the backend API. |